Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.1 CVE-2021-28692 inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such… Xen Mitigation only Fix from $1,9502021-06-30 HIGH 7.8 CVE-2021-35523 Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYST… Openvpn Client 2.0.32+ Fix from $1,9502021-06-28 HIGH 8.8 CVE-2021-33538 In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settin… Ie Wl Bl Ap Cl Eu Firmware after 1.16.18 Fix from $1,9502021-06-25 HIGH 7.8 CVE-2021-35448 Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder fe… Emote Interactive Studio No fix yet Fix from $1,9502021-06-24 HIGH 8.8 CVE-2021-23999 If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges t… Firefox 78.10 / 88.0+ Fix from $1,9502021-06-24 MEDIUM 6.5 CVE-2021-29951 The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start … Firefox 78.10.1 / 87.0+ Fix from $1,6002021-06-24 HIGH 8.8 CVE-2021-25650 A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially craft… Aura Utility Services after 7.1.3 Fix from $1,9502021-06-24 HIGH 7.8 CVE-2021-25651 A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Af… Aura Utility Services after 7.1.3 Fix from $1,9502021-06-24 HIGH 8.8 CVE-2021-34810 Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to exe… Download Station 3.8.16-3566+ Fix from $1,9502021-06-18 HIGH 7.8 CVE-2021-27483 ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to… Defibrillator Dashboard 2.2+ Fix from $1,9502021-06-16 HIGH 7.8 CVE-2021-25418 Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activit… Internet 14.0.1.62+ Fix from $1,9502021-06-11 HIGH 8.8 CVE-2021-28814 An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise… Helpdesk 3.0.4+ Fix from $1,9502021-06-11 HIGH 7.8 CVE-2021-0052 Incorrect default privileges in the Intel(R) Computing Improvement Program before version 2.4.6522 may allow an authenticated user to potentially ena… Computing Improvement Program 2.4.6522+ Fix from $1,9502021-06-09 HIGH 8.8 CVE-2021-33356EPSS 5% Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /in… Raspap after 2.6.5 Fix from $1,9502021-06-09 HIGH 7.8 CVE-2021-31969 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-06-08 HIGH 7.8 CVE-2021-31954 Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-06-08 HIGH 8.8 CVE-2021-27657 Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allow… Metasys after 11.0 Fix from $1,9502021-06-04 HIGH 7.8 CVE-2013-4536 An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on… Qemu 1.5.3+ Fix from $1,9502021-05-28 HIGH 7.8 CVE-2021-22118 In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation:… Spring Framework 5.2.15 / 5.3.7+ Fix from $1,9502021-05-27 HIGH 7.8 CVE-2021-22732 Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue… Spacelynk Firmware after 2.6.0 Fix from $1,9502021-05-26 HIGH 7.8 CVE-2021-22733 Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unau… Spacelynk Firmware after 2.6.0 Fix from $1,9502021-05-26 HIGH 7.8 CVE-2018-16497 In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as… Versa Analytics Mitigation only Fix from $1,9502021-05-26 CRITICAL 9.8 CVE-2020-28904 Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious co… Fusion after 4.1.8 Fix from $2,3002021-05-24 HIGH 7.8 CVE-2021-20713 Privilege escalation vulnerability in QND Advance/Premium/Standard Ver.11.0.4i and earlier allows an attacker who can log in to the PC where the prod… Qnd after 11.0.4i Fix from $1,9502021-05-24 HIGH 8.8 CVE-2021-24289 There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their us… Store Locator Plus after 5.5.14 Fix from $1,9502021-05-17 HIGH 7.8 CVE-2021-23891 Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating… Total Protection 16.0.32+ Fix from $1,9502021-05-12 HIGH 7.8 CVE-2021-31168 Windows Container Manager Service Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-05-11 HIGH 7.8 CVE-2021-31169 Windows Container Manager Service Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-05-11 MEDIUM 5.5 CVE-2021-21430 OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an Op… Openapi Generator 5.1.1+ Fix from $1,6002021-05-10 HIGH 7.0 CVE-2021-21428 Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documentation and configuration auto… Openapi Generator 5.1.0+ Fix from $1,9502021-05-10